From 01b2088dd3a4fea90d472061fc18ef202d9b1031 Mon Sep 17 00:00:00 2001 From: Malcolm Tyrrell Date: Thu, 5 Nov 2020 15:02:41 +0000 Subject: [PATCH 1/4] A missing bufferview was causing a crash. --- code/AssetLib/glTF2/glTF2Asset.inl | 33 ++++++++++++++++++++++-------- 1 file changed, 24 insertions(+), 9 deletions(-) diff --git a/code/AssetLib/glTF2/glTF2Asset.inl b/code/AssetLib/glTF2/glTF2Asset.inl index badf60f5c..396b1adf3 100644 --- a/code/AssetLib/glTF2/glTF2Asset.inl +++ b/code/AssetLib/glTF2/glTF2Asset.inl @@ -289,7 +289,8 @@ Ref LazyDict::Retrieve(unsigned int i) { // Unique ptr prevents memory leak in case of Read throws an exception auto inst = std::unique_ptr(new T()); - inst->id = std::string(mDictId) + "_" + to_string(i); + // Try to make this human readable so it can be used in error messages. + inst->id = std::string(mDictId) + "[" + to_string(i) + "]"; inst->oIndex = i; ReadMember(obj, "name", inst->name); inst->Read(obj, mAsset); @@ -637,15 +638,18 @@ inline void Accessor::Read(Value &obj, Asset &r) { const char *typestr; type = ReadMember(obj, "type", typestr) ? AttribType::FromString(typestr) : AttribType::SCALAR; - // Check length - unsigned long long byteLength = (unsigned long long)GetBytesPerComponent() * (unsigned long long)count; - if ((byteOffset + byteLength) > bufferView->byteLength || (bufferView->byteOffset + byteOffset + byteLength) > bufferView->buffer->byteLength) { - const uint8_t val_size = 64; + if (bufferView) + { + // Check length + unsigned long long byteLength = (unsigned long long)GetBytesPerComponent() * (unsigned long long)count; + if ((byteOffset + byteLength) > bufferView->byteLength || (bufferView->byteOffset + byteOffset + byteLength) > bufferView->buffer->byteLength) { + const uint8_t val_size = 64; - char val[val_size]; + char val[val_size]; - ai_snprintf(val, val_size, "%llu, %llu", (unsigned long long)byteOffset, (unsigned long long)byteLength); - throw DeadlyImportError("GLTF: Accessor with offset/length (", val, ") is out of range."); + ai_snprintf(val, val_size, "%llu, %llu", (unsigned long long)byteOffset, (unsigned long long)byteLength); + throw DeadlyImportError("GLTF: Accessor with offset/length (", val, ") is out of range."); + } } if (Value *sparseValue = FindObject(obj, "sparse")) { @@ -737,13 +741,24 @@ inline void CopyData(size_t count, } } } + +inline std::string getContextForErrorMessages(const std::string& id, const std::string& name) +{ + std::string context = id; + if (!name.empty()) + { + context += " (\"" + name + "\")"; + } + return context; +} + } // namespace template void Accessor::ExtractData(T *&outData) { uint8_t *data = GetPointer(); if (!data) { - throw DeadlyImportError("GLTF2: data is nullptr."); + throw DeadlyImportError("GLTF2: data is nullptr when extracting data from ", getContextForErrorMessages(id, name)); } const size_t elemSize = GetElementSize(); From 0af05e7a6053babfa8fabbd8ac09299c965cb0c7 Mon Sep 17 00:00:00 2001 From: Malcolm Tyrrell Date: Thu, 5 Nov 2020 15:10:52 +0000 Subject: [PATCH 2/4] Better message --- code/AssetLib/glTF2/glTF2Asset.inl | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/code/AssetLib/glTF2/glTF2Asset.inl b/code/AssetLib/glTF2/glTF2Asset.inl index 396b1adf3..106c1fd51 100644 --- a/code/AssetLib/glTF2/glTF2Asset.inl +++ b/code/AssetLib/glTF2/glTF2Asset.inl @@ -758,7 +758,7 @@ template void Accessor::ExtractData(T *&outData) { uint8_t *data = GetPointer(); if (!data) { - throw DeadlyImportError("GLTF2: data is nullptr when extracting data from ", getContextForErrorMessages(id, name)); + throw DeadlyImportError("GLTF2: data is null when extracting data from ", getContextForErrorMessages(id, name)); } const size_t elemSize = GetElementSize(); From 34e3e6293ae0f4d36b93e472fba44a16a574f44d Mon Sep 17 00:00:00 2001 From: Malcolm Tyrrell Date: Fri, 6 Nov 2020 09:57:48 +0000 Subject: [PATCH 3/4] Style --- code/AssetLib/glTF2/glTF2Asset.inl | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/code/AssetLib/glTF2/glTF2Asset.inl b/code/AssetLib/glTF2/glTF2Asset.inl index 106c1fd51..cfa9cb142 100644 --- a/code/AssetLib/glTF2/glTF2Asset.inl +++ b/code/AssetLib/glTF2/glTF2Asset.inl @@ -638,8 +638,7 @@ inline void Accessor::Read(Value &obj, Asset &r) { const char *typestr; type = ReadMember(obj, "type", typestr) ? AttribType::FromString(typestr) : AttribType::SCALAR; - if (bufferView) - { + if (bufferView) { // Check length unsigned long long byteLength = (unsigned long long)GetBytesPerComponent() * (unsigned long long)count; if ((byteOffset + byteLength) > bufferView->byteLength || (bufferView->byteOffset + byteOffset + byteLength) > bufferView->buffer->byteLength) { @@ -742,11 +741,9 @@ inline void CopyData(size_t count, } } -inline std::string getContextForErrorMessages(const std::string& id, const std::string& name) -{ +inline std::string getContextForErrorMessages(const std::string& id, const std::string& name) { std::string context = id; - if (!name.empty()) - { + if (!name.empty()) { context += " (\"" + name + "\")"; } return context; From 0f246edb97d1f557bf3307f16be85a88377dab82 Mon Sep 17 00:00:00 2001 From: Malcolm Tyrrell Date: Fri, 6 Nov 2020 13:43:16 +0000 Subject: [PATCH 4/4] Prevent GetValue from corrupting memory --- code/AssetLib/glTF2/glTF2Asset.inl | 22 ++++++++++++++++------ 1 file changed, 16 insertions(+), 6 deletions(-) diff --git a/code/AssetLib/glTF2/glTF2Asset.inl b/code/AssetLib/glTF2/glTF2Asset.inl index cfa9cb142..b4fbc3fad 100644 --- a/code/AssetLib/glTF2/glTF2Asset.inl +++ b/code/AssetLib/glTF2/glTF2Asset.inl @@ -835,9 +835,11 @@ template T Accessor::Indexer::GetValue(int i) { ai_assert(data); ai_assert(i * stride < accessor.bufferView->byteLength); + // Ensure that the memcpy doesn't overwrite the local. + const size_t sizeToCopy = std::min(elemSize, sizeof(T)); T value = T(); - memcpy(&value, data + i * stride, elemSize); - //value >>= 8 * (sizeof(T) - elemSize); + // Assume platform endianness matches GLTF binary data (which is little-endian). + memcpy(&value, data + i * stride, sizeToCopy); return value; } @@ -866,6 +868,14 @@ inline void Image::Read(Value &obj, Asset &r) { } } else if (Value *bufferViewVal = FindUInt(obj, "bufferView")) { this->bufferView = r.bufferViews.Retrieve(bufferViewVal->GetUint()); + if (Value *mtype = FindString(obj, "mimeType")) { + this->mimeType = mtype->GetString(); + } + if (!this->bufferView || this->mimeType.empty()) + { + throw DeadlyImportError("GLTF2: ", getContextForErrorMessages(id, name), " does not have a URI, so it must have a valid bufferView and mimetype"); + } + Ref buffer = this->bufferView->buffer; this->mDataLength = this->bufferView->byteLength; @@ -873,10 +883,10 @@ inline void Image::Read(Value &obj, Asset &r) { this->mData.reset(new uint8_t[this->mDataLength]); memcpy(this->mData.get(), buffer->GetPointer() + this->bufferView->byteOffset, this->mDataLength); - - if (Value *mtype = FindString(obj, "mimeType")) { - this->mimeType = mtype->GetString(); - } + } + else + { + throw DeadlyImportError("GLTF2: ", getContextForErrorMessages(id, name), " should have either a URI of a bufferView and mimetype" ); } } }